Solved

Exchange 2003 Server Queue Filling up!

Posted on 2012-12-27
6
299 Views
Last Modified: 2012-12-28
I've read every article and have done practically everything. I've made sure there isn't an open relay, I've applied Recipient Filtering ( Checked "Filter recipients who are not in the Directory" ), Sender Filtering, Connection Filtering, Sender ID Filtering, I've gone to Default SMTP Virtual Server - Access - Relay and ticked "Only the list below" and unchecked "Allow all computers which successfully authenticate to relay regardless of the list above" as well as left the "Computer list" blank under "Only the list below",  I've disabled port 25 on the firewall, changed the admin password, disabled accounts that weren't being used, enabled logging on NDRs and haven't seen the event id 1708 (to see if another account has been compromised), enabled Tar Pit, I've tested to make sure it isn't a DNS problem, and disabled NDR....

I'm still continuing to get hundreds of thousands of NDRs from unrecognized email accounts in the queue. I have no idea what to do to solve this problem :-( If someone could please point me in the right direction I'd appreciate it!
0
Comment
Question by:stevegarri
6 Comments
 
LVL 20

Expert Comment

by:agonza07
ID: 38726157
Maybe they are not yours, maybe someone is just spoofing your email accounts and you're just getting the NDRs.

Check the headers on the NDR to see where they originated from. Might not be your IP.
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 38726234
Does your server receive emails directly or via a 3rd party filter service?

If direct, trial Vamsoft (www.vamsoft.com) and the pain will go away.

I'm assuming the sender of the messages is Postmaster@yourdomain.local?

Alan
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 38726721
Even after closing the holes, you will still see messages pile up for some time afterwards. When a server has been abused, the spammer will send 1000s of messages as quickly as possible and it takes time for Exchange to process them. I have seen email contiue to pile up for six or seven hours after the server was disconnected from the internet. You will just have to wait it out unfortuantely.

Simon.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 

Author Comment

by:stevegarri
ID: 38726832
The email has been piling up for over 24 hours. Message ID is adsfdjkafh234223@mail.mydomain.com

Sender is noreply@mail.yahoo-inc.com or tw-edm-auction@yahoo-inc.com

I've been constantly having to use the aqadmcli.exe tool to clear the queue :-( It's so wierd and I can't figure out where they are coming from. Anyone have any idea how I can stop this?
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 500 total points
ID: 38726859
That is what happens.
There will be 1000s of messages that Exchange is still processing. What you see in the queue is just the tip of what could be inside Exchange still waiting to be processed.

Simon.
0
 

Author Closing Comment

by:stevegarri
ID: 38728390
Yup you were right. A few hours later it ended up leveling off and zero-ing out :-) Exchange is all good! Thanks!
0

Featured Post

[Webinar] Disaster Recovery and Cloud Management

Learn from Unigma and CloudBerry industry veterans which providers are best for certain use cases and how to lower cloud costs, how to grow your Managed Services practice in IaaS clouds, and how to utilize public cloud for Disaster Recovery

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
In this article, I will show you HOW TO: Perform a Physical to Virtual (P2V) Conversion the easy way from a computer backup (image).
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now